Search tools

Linux file permissions

chmod 600: what it means and when to use it

chmod 600 lets the owner read and write the file and gives nobody else any access to it.

600 rw-------
What chmod 600 allows for each class of user
WhoDigitRead WriteExecute
Owner 6 Yes Yes No
Group 0 No No No
Everyone else 0 No No No

How chmod 600 works

The 6 is read plus write for the owner, and the zeros shut out the group and everyone else. There is no execute permission, which is correct for data files.

600 is the standard for secrets. SSH private keys have to be 600 or SSH will not load them, and the same care applies to .env files, database credentials and API tokens on a shared machine.

Where 600 belongs

  • SSH private keys
  • .env files and other credential files
  • Personal data files on a shared server

The command

Both of these set exactly the same permissions. The number is shorter; the letters are easier to read back later.

chmod 600 filename
chmod u=rw,g=,o= filename

If a service needs to read the file, make that service's user the owner rather than widening the permission to 644.

Open 600 in the chmod calculator